Live data from Hacker News

GDPR Enforcement Tracker: List of GDPR fines

enforcementtracker.com

241–250 of 301 posts

Re: GDPR Enforcement Tracker: List of GDPR fines

#241
post #228

Earlier quoted context omitted.

Not a harassment campaign as such, it seems. He was mad about something, and mailed a bunch of politicians and press his complaints. Complaints, sometimes bordering on being libelous, according to the agency which fined him, not death threats. He was fined solely based upon the email addresses being visible to all recipients, not because of the content of his mails, said a spokesperson. However, he was a repeat offen…

Isn't one of the points of separation of power that the government (executive branche) should not have priority access to the judicial branche? Fining individuals, even loony ones, while not even attempting to fight the big battles (FAANG, personal data trading for 'profiling' or even government profiling within the EU) is imho just preposterous.

What sort of priority access was used in this case? Maybe they just filed a complaint like anyone else.

Re: GDPR Enforcement Tracker: List of GDPR fines

#243

What do you do if e.g. Instagram ignores your GDPR requests? I have sent them multiple emails about misuse of my personal data and they only replied with a template that didn't address my emails?

You inform your national data protection authority:

https://edpb.europa.eu/about-edpb/board/members_en

Re: GDPR Enforcement Tracker: List of GDPR fines

#244

Earlier quoted context omitted.

You appear to be spreading false rumors about them issuing warnings even though they don’t have to. When I organized the data on this site by fine amount, not a single case on the front page said anything about any of the companies fined having received a single warning. So, by comparing this to legal situations where “ it never happens” you are purposely misrepresenting the risk of receiving a fine under GDPR withou…

Why would you expect a site built to report GDPR fines and penalties to report GDPR warnings? ICO haven't yet released aggregate figures for GDPR, it's too soon. GDPR is a minor update of DPA, and they have released aggregate numbers on that for a while. Fines are levied in a tiny minority of cases. Warnings are far more common, as is steady escalation. The expectation here is the proportions will remain the same und…

>GDPR is a minor update of DPA

It is not a minor update[1]. The Information Commissioner's Office is extremely aware and vexed, given the current state of affairs, that Data Protection Act 2018, needs to be aligned as closely to the GDPR to allow for information to flow freely after Brexit (Article 45)[2][3].

Furthermore, ICO has not been the epitome of a regulatory body enforcing the law to it's fullest extent, for which it has had the remit for ─ by stopping business' doing a runner or imposing maximum fines, neither has it had a good record on collecting the fines issued. Although, it has made a meal of some of the high profile rain-making cases which have already been in the public eye. It is ironic that there are no real details forthcoming from ICO and one has to resort to FoI requests to get any information on it's previous escapades under DPA 98![4]

[1] https://www.dpocentre.com/difference-dpa2018-and-gdpr/

[2] https://gdpr-info.eu/art-45-gdpr/

[3] https://ico.org.uk/for-organisations/data-protection-and-bre...

[4] https://www.theregister.co.uk/2018/05/25/millions_of_pounds_...

Re: GDPR Enforcement Tracker: List of GDPR fines

#245

Earlier quoted context omitted.

The examples here make clear that "a clear reason for collecting everything" means an ironclad justification for each field, each bit of precision, each minute of retention. That is not a casual thing. As in, one of the fines here is for retaining a phone number to fulfill a need to communicate, when postal mail could have worked instead. It is doable, if you have the lawyers and the time. But that's not a degree of…

If you don't need a phone number why collect a phone number? I might need it later is not a clear reason!

Also, the fine (if we are talking about the Danish one) was not for collecting a phone number. It was for retaining it after the retention limit (in this case 2 years, and they kept them for 5 years) without a good cause. The company argued they were and essential part of the database. People love to make GDPR look bad, but it's often not as bad as it looks from a one line summary.

Re: GDPR Enforcement Tracker: List of GDPR fines

#247

At the time of the GDPRpocalypse last year, there were a lot of discussions here, and a lot of FUD being slung around about how if your US website wasn't 100% GDPR-compliant you'd be handcuffed if you set foot in an EU airport bla bla bla, or that minor infractions would incur the maximum penalty of millions of euro, bankrupting your awesome adtech startup bla bla bla. Most of it was fueled by the clash between US an…

> Seems we were right. Arguably, and so far . There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses, and just because nobody's been hanged over it in year one doesn't mean it won't be abused, oppressive, or have other negative unintended consequences in the future.

> There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses

food safety regulations have a chilling effect on businesses that would try and sell arsenic-laced food.

dumping poisonous byproducts of a manufacturing process in a river will also net you a stomping by the society, another instance of a chilling effect of regulations.

i'm happy with these chilling effects, they relieve me of the need for constant vigilance. they enable our society to function. we do not need to fear for our mental of physical health and (private) lives all the time, we can focus on higher-order things instead.

Re: GDPR Enforcement Tracker: List of GDPR fines

#248
post #154

Many people are complaining about some fines, but here are some others I see that are evidence of this working extremely well: - A police officer was fined for using his department's tools to get someone's private phone number for his personal use - A rental agency was fined for leaving renter's private data (ids, etc) open to the public for six months after being notified of the vulnerability - A company was fined b…

All but maybe one of those looks like it was illegal prior to GDPR, so I'm not sure GDPR is what you're praising.

GDPR unified and clarified all the different directions and laws active in EU member states before. So while most of those indeed were illegal before in one or more member states, all of them are illegal now in all member states. As such, GDPR does not really extend privacy protection de jure but merely helps enforcement by unifying protections de jure and hence allowing for a more efficient enforcement de facto.

Re: GDPR Enforcement Tracker: List of GDPR fines

#249

Two of these are much more intense than I would have guessed: >The fine concerned the proceedings related to the activity of a company which processed the data subjects’ data obtained from publicly available sources, inter alia from the Central Electronic Register and Information on Economic Activity, and processed the data for commercial purposes. The authority verified incompliance with the information obligation i…

RE first example, read the linked official report[0]. Some choice quotes:

"the company did not meet the information obligation in relation to over 6 million people. Out of about 90,000 people who were informed about the processing by the company, more than 12,000 objected to the processing of their data."

"In the relevant case, the entity had postal addresses and telephone numbers and could therefore comply with the obligation to provide information to the persons whose data are being processed. Therefore, this case should be distinguished from another case decided by the Polish DPA a few years ago, when another company did not have such addresses at its disposal."

"The President of the Personal Data Protection Office found that the infringement of the controller was intentional, because - as it was established during the proceedings - the company was aware of the obligation to provide relevant information, as well as the need to directly inform persons."

"While imposing the fine, the authority also took into account the fact that the controller did not take any action to put an end to the infringement, nor did it declare its intention to do so."

This is precisely the kind of crap GDPR was meant to address, and I very much like the decision made here.

EDIT: If I'm Googling correctly and found the correct company, then here's an extra irony: they actually offered services and advice to companies in preparing for GDPR coming into force. It's safe to say they were fully aware of the obligations under law when they performed data mining on government databases of entrepreneurs.

--

[0] - https://uodo.gov.pl/en/553/1009

Re: GDPR Enforcement Tracker: List of GDPR fines

#250

Earlier quoted context omitted.

> Seems we were right. Arguably, and so far . There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses, and just because nobody's been hanged over it in year one doesn't mean it won't be abused, oppressive, or have other negative unintended consequences in the future.

> There are sites that just block requests from the EU, there's a difficult-to-measure chilling effect on small businesses food safety regulations have a chilling effect on businesses that would try and sell arsenic-laced food. dumping poisonous byproducts of a manufacturing process in a river will also net you a stomping by the society, another instance of a chilling effect of regulations. i'm happy with these chill…

I feel differently about it, but I think that's totally fair. Just pointing out that it's not quite the case that opponents' predictions turned out to be wrong.

Some did, at least for the first year. But some haven't.

Post reply on HN